# Authentication and API keys

Create, use, limit, rotate and protect your API keys.

> https://nezhagate.com/en/docs/guide/api-keys

## Create an API key

1. Sign in, open the API Keys page of the console and give the key a name that says what it is for.

2. Set any limits you want (requests per minute, budgets, allowlists); you can change them later.

3. The new key appears in the list; click Copy to get the full key (it starts with `sk-`) and keep it somewhere safe, such as an environment variable on your server.

## Send the key with each request

OpenAI-compatible endpoints take an `Authorization: Bearer` header; the Anthropic endpoints take `x-api-key` and also accept `Authorization: Bearer`. Keep the key in an environment variable, not in your code.

```
Authorization: Bearer YOUR_API_KEY
```

```
x-api-key: YOUR_API_KEY
anthropic-version: 2023-06-01
```

```
import os
from openai import OpenAI

# export NEZHAGATE_API_KEY=sk-...   (never commit the key)
client = OpenAI(base_url="https://nezhagate.com/v1", api_key=os.environ["NEZHAGATE_API_KEY"])
```

## Put limits on a key

Each key can have its own limits, independent of the others:

| Setting | What it does |
| --- | --- |
| **Requests per minute** | The most requests this key may send in a minute. |
| **Daily budget** | The most this key may spend per day (UTC), in US dollars. |
| **Total limit** | The most this key may spend in total, in US dollars; good for automation that must not run away. |
| **Model allowlist** | This key may call only the models listed. |
| **IP allowlist** | Only requests from the listed IPs or ranges are accepted. |

[What you get back when a limit is hit →](https://nezhagate.com/en/docs/guide/rate-limits#per-key)

## Disable and rotate

1. Create a new key and switch your code over to it.

2. Once the new key is working, disable the old one in the console. It takes effect at once; requests with the old key then get 401.

3. If you think a key leaked, disable it first, then create a new one.

## Keeping keys safe

- Keep keys on your server. Never put them in a web page, an app or a public repository.

- Use a separate key per app and per environment, so a problem means disabling just that one.

- Give keys used by automation or third-party tools a budget or total limit.

- If your servers have fixed IPs, turn on the IP allowlist.

## The balance belongs to the account

All keys of an account share one balance. `GET /v1/usage` with any key returns the account's balance and spend.
